This signature file may be used to cryptographically verify file integrity, like this:: $ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-asp-net-apache-12.0-squeeze-x86-openstack.tar.gz.sig gpg: Signature made Tue Aug 21 15:10:19 UTC 2012 using RSA key ID A16EB94D gpg: Good signature from "Turnkey Linux Release Key For your convenience we also include file checksums: * sha1sum 635105b61a03661f7879a9e3e0c72e21f69305d1 * md5sum 47ab19b24a303d2dbb0f372ac4bc974a You can calculate these on your end and compare to check for errors, but cryptographic verification is recommended for security reasons. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAABAgAGBQJQM6TPAAoJEIXCXpWhbrlN1S0H/jdhoamKRfOJsLepGT1q6y5T n3l/FXc3Z8ht/3n5x+AsFKSIXXQ+bhqxCCsVbDMoQmt9iRiwqMOOMQrrY2toW+4H xBkhIBbmVi0CD7GQHCFAFashxOUWw7/k/08Bz2eSOekqJ32aRdM/jRY9ur4FuW4m gn+UmuXaAbVBHP57FaqpB5AcphF1cxge6aAwPAD0kr/OXxuwHEvZYOPEnhTF2Rqd LAbqwPGG7vuNGk+Hl37Ttkz8QvawtB2UEefFu7lm/0a9JocPZFgKPihWF3PKmX61 zt6UGd3WmP2RalgmfPHOCRV/M7uSgYy93rhojskgAr9AqpuwLb66P4YFhdiHutM= =P35C -----END PGP SIGNATURE-----